MIT-CTP-4099 



Quantum state restoration and single-copy tomography 

Edward Farhi,* David Gosset,^ Avinatan Hassidim/ and Andrew Lutomirski^ 
Center for Theoretical Physics, Massachusetts Institute of Technology, Cambridge, MA 02139 

Daniel Nagaj^ 

Research Center for Quantum Information, Institute of Physics, 
Slovak Academy of Sciences, Dubravskd cesta 9, 845 11 Bratislava, Slovakia 



Given a single copy of an n qubit quantum state \tp), the no-cloning theorem greatly limits the 
amount of information which can be extracted from it. Moreover, given only a procedure which 
verifies the state, for example a procedure which measures the operator we cannot prepare 

in time polynomial in n. In this paper, we consider the scenario in which we are given both a single 
copy of and the ability to verify it. We show that in this setting, we can do several novel things 
efficiently. We present a new algorithm that we call quantum state restoration which allows us to 
extend a large subsystem of to the full state, and in turn this allows us to copy small subsystems 
of In addition, we present algorithms that can perform tomography on small subsystems of 
and we show how to use these algorithms to estimate the statistics of any efficiently implementable 
POVM acting on \tl>) in time polynomial in the number of outcomes of the POVM. 



Quantum mechanics places constraints on what can be done with only a single copy of an unknown state. The 
no-cloning theorem says that it is impossible to copy such a state. Measuring an observable on an unknown state 
generically damages it. Learning the full description of a state or even the description of a small piece of it cannot be 
done with only a single copy of it. 

We are interested in the additional power given by the ability to verify a state. Given a single copy of an unknown 
quantum state \ip) and a verifier, that is a black box (or quantum circuit) which measures the operator P — \i(j)(ip\, 
the no-cloning theorem no longer applies. In this setting, we present novel algorithms that can copy small parts of 
the state and make measurements on \ifj) without damaging the state. One situation where such a verifier exists is 
when is the unique ground state of a particular gapped local Hamiltonian which we know. Measuring the energy 
of l^) gives the ground state energy E$. We can then use Eq and the Hamiltonian H to verify whether any state has 
energy Eq. 1 

To understand quantum state restoration, first consider a classical problem. Suppose that there is some unknown 
n-bit string z = zazb, where za is the first n — k bits of z and zb is the last k bits. Suppose further that there is a 
function 



on n-bit strings that tests whether they are equal to z. If we are given za and the ability to evaluate /, we can find z 
by randomly guessing: we pick a random A:-bit string xb and evaluate / (zaXb), repeating until we get / = 1. This 
finds z in expected time 2 k . 
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Quantum state restoration is a straightforward quantum generalization of this classical algorithm, which surprisingly 
works even on entangled states. If \ip) lives in the Hilbert space Ha <8> T~Lb, our algorithm takes as input the part of 
\4>) that lives in subsystem A and uses P to produce as output the state l^) in expected time O (poly(dim - Hs)). It 
works by randomly guessing the part of \ip) that lives in subsystem B and measuring P. On a successful iteration 
(i.e. if the measurement outcome is 1), then \ip) is recovered. On a failed iteration, there is minimal damage to the 
part of the state in subsystem A and we can try again. 

This can be used to copy small subsystems of \tp): if \ip) has the reduced density matrix pg on a small subsystem 
B, we can set aside subsystem B and then use state restoration to extend subsystem A to the full state \ip). We 
are left with \tp) and a mixed state ps- If we use this to obtain multiple copies of ps, we can perform tomography 
on subsystem B. We call this application single-copy tomography, and we give two more specialized algorithms to 
do the same thing. All these algorithms have running time polynomial in the dimension of subsystem B. We also 
give a reduction from estimating the statistics of a general POVM measurement (even if it includes noncommuting 
operators) to single-copy tomography, with running time polynomial in the number of POVM operators. 

Our original motivation for developing these algorithms was to understand the security of a class of public-key 
quantum money schemes. Public- key quantum money is a quantum state that can be produced by a bank and 
verified by anyone — ideally, the verification algorithm is a projector onto the state in question [1, 2, 7]. The definition 
of quantum money requires that no one other than the bank can efficiently produce states that pass verification, 
and when a state passes verification it is returned undamaged by the procedure. Whether or not secure quantum 
money protocols exist is an open question. However, algorithms such as quantum state restoration and single-copy 
tomography rule out a large class of possible quantum money schemes. 

The simplest example of a quantum money scheme that is broken by our algorithm is based on product states. The 
bank chooses a string of n uniformly random angles 0j between and 2tt. This string is a classical secret known only 
to the bank. Using these angles, the bank generates the state \ip) = where \9i) = cos6'i|O)-|-sin0i|l) and chooses 

a set of (say) 4-local projectors {Pi} which are all orthogonal to \ip). This set is chosen to be large enough so that 
|?/>) is the only state in the intersection of the zero eigenspaces of all of the projectors. The quantum money consists 
of the state and a classical description of the projectors 2 . The bank must choose a new set of angles {6*j} for each 
quantum money state it produces; otherwise standard tomography can break this protocol. Anyone can verify the 
money by measuring the projectors. Since a good money state is an eigenstate of the projectors, the measurement 
passes along good money undamaged. 

At first glance, product state quantum money seems promising. First, given only the state l^), the no-cloning 
theorem prevents anyone from making a second copy. In general, given only a set of 4-local projectors, the problem of 
finding the corresponding angles (if they exist) is NP-complete (although in our case the projectors are chosen from 
a specific distribution and there is a planted solution, so the problem may be easier). However, given both the state 
\ip) and the projectors, \ip) can be efficiently copied using quantum state restoration. We use the quantum money's 
verifier as our projector P = \ip){ip\. We can then copy the qubits one at a time. To copy the first qubit, a simplified 
version of quantum state restoration proceeds as follows: 

1. Set aside the first qubit. We are left with the state |#2) • ■ ■ \&n)- 

2. Add a new register at the beginning containing a random one-qubit state. We now have a state which can be 
written as 

(al^+^r))!^) ••■!#„) 

where (0i\9^~) — and a and (3 are unknown random variables. 

3. Verify the quantum money. This produces either the desired state or an invalid quantum money state 

\ei)\e 2 )---\0n) 

with equal probability (averaged over the choice of the random state in step 2). If we have produced the desired 
state, then we have cloned the first qubit: we have both the copy in the |^) and the qubit that we set aside in 
step 1. If not, then we discard the qubit \Q±) and go back to step two and repeat until we get \0\). 



2 The bank must also digitally sign the description of the projectors using a classical digital signature protocol which is a secure against 
quantum adversaries. Such protocols are believed to exist. 
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Repeating this procedure for each qubit allows us to clone the state \tp) in linear time. 

The algorithm we just described can copy the full n-qubit state \ip) because is a product state. We can think 
of this algorithm as first removing a subsystem of \tp) (step 1) and then recovering the state \ip) from the part that 
remains (steps 2 and 3). Surprisingly, a small modification of steps 2 and 3 leads to an algorithm that efficiently 
restores small missing subsystems, even on entangled states: this is quantum state restoration. 

Our paper is structured as follows. In section II, we present the quantum state restoration algorithm and analyze 
its running time. In section III, we present two alternative algorithms for single-copy tomography, one of which is 
asymptotically faster than quantum state restoration. Finally, we give several scenarios in which new algorithms could 
be developed using the techniques in this paper. 

II. QUANTUM STATE RESTORATION 

Quantum state restoration takes as input a large subsystem of a state (this subsystem could be, for example, 
the first n—k qubits of the n qubit state and, using the ability to measure the projector P = \il))(ip\, reconstructs 
the full state 

Theorem 1. Suppose that is an unknown quantum state in a Hilbert space H.a ® Hb and we are given oracle 
access to a coherent measurement of P = IV'XV'I (that is, the oracle performs the operation P (£> I + (1 — P) ® cr x on 
the original Hilbert space plus a single-qubit ancilla). Then there exists an efficient quantum algorithm that takes as 
input a mixed state in H.a with density matrix Tr^ IV 7 ) (^1 an d outputs \ip) . This algorithm makes an expected number 

O ^(dim"Hs) 2 ^ of calls to the measurement oracle. 

The idea is that any state \ip) on a Hilbert space Ha <£> Hb (where d is the dimension of Hb) can be Schmidt 
decomposed as 

x 

i=l 

where x is the Schmidt rank of (note that \ < d). If we start with the state \tp) and set aside the part that lives 
on Hb, then we are left with the mixed state pa = T^b IV'XV'L which has all of its support on the Schmidt basis 
span {|iti)}. From pa, we can construct the state pa <8> ^ on Ha®Hb- We now measure the projector P. If we obtain 
the outcome 1, then we are left with the state \ip), If not, we discard (i.e. trace out) Hb, leaving a state on Ha that 
still has all of its support on the Schmidt basis. We then try again until we obtain the outcome 1. If all the pi are 
equal, then each attempt succeeds with probability and the entire algorithm finishes in an expected number of 
iterations \d. For general values {pi}, the expected running time is still exactly \d, although the distribution of the 
running time becomes more complicated. 

We now summarize the quantum state restoration algorithm. 

1. Start with the state 1^) G Ha ® Hb and set aside the part of \ifj) that lives in subsystem B. We are left with 
the mixed state 

Pa = Tr B \ip)(ip\. 

2. Add a random state on subsystem B. The state is now 

I 

PA ® j. 

a 

3. Measure the projector P — |-0)(t/>|. If the outcome is +1 then you are done: you still have the original copy of 
subsystem B that you set aside and you have recovered the state If not, discard subsystem B and repeat 
from step 2. 

We now show that the expected running time of this algorithm is \ ' d < d 2 (measured in number of uses of P) . 
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Iteration number 



Figure 1: Probability of restoring the state on a given iteration conditioned on all previous iterations failing. Condi- 
tioned on failing every time, the first two flat regions are metastable states and the third is stable. In this graph, 
= VI - 10- 2 - 10- 4 |0}a|0)b + VT(F2jl) A |l) B + VW^\2) A \2) B , AimH B 



10, and the expected number of iterations 



required is 30. 



A. Running Time of Quantum State Restoration 



In the simple case where all of the p t are equal, then the initial state pa is the fully mixed state over the span{|ui)}. 
In this case, if you measure in step 3, the density matrix left in register A after discarding register B is unchanged. 
The algorithm terminates with probability on each iteration, finishing in an expected number of iterations x • d- If 
the pi are not all equal, then the algorithm can reach bad states where most of the weight is on low-weight elements of 
the Schmidt basis. When this happens, the chance of success on any given iteration drops (see Fig. 1 for an extreme 
example), but the probability of reaching these bad states decreases with the corresponding p im Surprisingly, these 
effects exactly cancel, and the expected number of iterations required to restore the state is x ' d regardless of the 
values of the pi . 

To prove this, we define two maps 

F (a) = Tr B 
Fi(a) =Tr B 



(l-MM)k® j) (i-IV')W) 



Here Fb(cr) is the unnormalized density matrix obtained by measuring P on the state given by the density matrix 
a, conditioned on the measurement outcome 6 G {0, 1}. The probability of obtaining a sequence of measurement 
outcomes 6i, 62, • • • , 6 m , starting with the state a is then given by 



Pr [{hb 2 , b 3 , b m } | a] = Tr[F bm o • • • o F bl {a)], 

which can be seen by induction: 

Pr [{bib 2 , b 3 , b m } \ v] = Pr [b m \ a, {61,62, h, b m -i}} 

x Pr [{61,62,63, ...,6 m _i} I a] 

= TrF b ( ' 
\Tr{F bm ^ o---oF bl (a)) 

x Tr (F bm _ 1 o..-oF bl (a)) 

= Tr F bm (F bml o ■■ ■ o F bl (a)). 



(1) 
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We can use this equation to write an explicit formula for the expected number of measurements T (a), starting with 
the state a: 



T{a) = ^fc-Pr [{0, 0, . . . , 0, 1} | cr] 



fe=1 k-i 



^fc-Tr[F 1 o J F o...oF ( ( r)]. (2) 



fc=i 



As written, this formula is difficult to evaluate, but we can see that it is linear in a. We are interested in the quantity 
T{pa), which we expand as 

x 

T( PA )=j2pinWi){ui\). (3) 

i=l 

We expand T(\ui)(ui\) by conditioning on the outcome of the first measurement: 

Fo(\u t )( Ul \) \\ 



T(\ Ui )( Ui \) = Pr [1 | |ui)<Ui|] +Pr[0||u i )(u i |] [l + T 
= l + T(f (k>H)) 



Pr [0| |ui)<t*i|] 



= 1 + T \ui){ui\ -2^\u i ){u i \ + -±^Tp j \u j ){v 
\ ' J =1 

= 1 + (l - 2|) T(\ Ui ){ Ui \) + ^J2p J T(\u ] )(u J \) . 
Using (3), this can be transformed into 

2piT(\ui)(ui\) -piT(p A ) = d. 
Summing both sides over i = 1, . . . ,x using ^2pi — 1 and (3) again, we obtain 

t (Pa) =X-d, 

which is the desired result. This proves theorem 1. 

III. SINGLE-COPY TOMOGRAPHY AND ESTIMATION OF MEASUREMENT STATISTICS 

We expect that quantum state restoration will most commonly be used to perform tomography on a single copy of 
a verifiable quantum state. We can perform several different types of tomography, and we give algorithms for some 
types that are faster than quantum state restoration. 

General tomography on a subsystem 

In the simplest case, we have a single copy of an unknown state and access to the measurement P — \i>)(ip\ and 
we would like to estimate properties of the density matrix ps = Tr^ |f/')(V , l f° r a subsystem B. We can do this by 
using quantum state restoration to prepare many unentangled states, each with (independent) density matrixes pb- 
We can then use any standard state tomography algorithm on these states. 

Measurement of a subsystem in an orthogonal basis 

For many applications, it is sufficient to estimate the probabilities = Tr of obtaining the outcome 

i if one were to measure subsystem B of \ip) in the orthonormal basis Quantum state restoration can sample 

these probabilities directly. We discuss this application in section III A. 

In sections III A and IIIB, we present two other specialized algorithms to compute these probabilities. 
Both algorithms measure the one at a time by considering the statistics of the two-outcome measurements 
{|*)-b(*|bi I — K)b(*|b}; an d both are based on previously presented schemes for amplifying QMA verifiers [6, 8]. 
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In each case, we fix a precision S > and an error probability e > and compute the running time to produce 
estimates qf st such that 

\ti*-Qi\<S 

for all i with probability at least 1 — e. 

Estimation of the statistics of any POVM 

We can use any of our algorithms to estimate the statistics of a general measurement (on the complete state, not 
just a subsystem). This is because a general POVM measurement can be reduced to a measurement of a subsystem 
in an orthogonal basis, as we now review. Given an efficiently implement able POVM {Ei} where i E {1, . . . , d}, we 
can implement a unitary operator U such that 

d 

U(\<p) A \l) B ) = ^2[^/E i \cj>) A ) \i) B 

i=l 

for any state \<f>). If we work in a two-register Hilbert space, where register A can hold \(j>) and register B has dimension 
d, then the probability of measurement outcome i when the POVM is measured on \<p) is equal to 

{<t>\Ei\<l>)=Tc\p B \i) B {i\ B \ 

where p B = Tr^ [U\^ A \1) B (1\ B (^\ A U^. If we define 

IV) = u\4>) A \i) B 
p' = \ii){4)\ = upu^ 

then \ip) can be efficiently prepared (given \<f>)) and P' can be efficiently measured. Now we can use any of the 
algorithms to estimate the measurement statistics of subsystem B of using the projector P' in the computational 
basis (that is, any of the algorithms below) to estimate the probabilities ((f>\Ei\<f)) — Tr [|i)(i|Ps]. After estimating the 
probabilities, we uncompute U to recover the initial state \<p). We summarize this ability with the following theorem. 

Theorem 2. Suppose that \<j>) is an unknown quantum state and we are given oracle access to a coherent measurement 
of P = \<j>)(<j)\ (that is, the oracle performs the operation P®I+(1 — P)®a x on the original Hilbert space plus a single- 
qubit ancilla). Fix < e < 1, 5 > 0, and an efficiently implementable d-outcome POVM given by operators {Ei}. 
Then there exists an efficient quantum algorithm that takes as input a single copy of \(f>) and outputs an undamaged 
copy of \(f>) along with estimates qf st such that 

\q? st - (mm < * 

for all i with probability at least 1 — e. This algorithm uses an expected number O ( | log ( )) calls to the measurement 
oracle and the POVM. 

The algorithm which achieves this running time is given in section IIIB2. 

If we want to perform tomography on a subsystem of \<p), we can use theorem 2 to estimate an informationally 
complete POVM on that subsystem. 



A. Using quantum state restoration to estimate measurement statistics 



In this section we consider the running time of estimating the probabilities qi — Tr [/9b |i) B (i\ B ] on a given state 
using quantum state restoration. We do this by repeatedly measuring register B and then restoring the state. Let 
be the number of times we observe outcome i in N trials. Our estimate of qi is 



1i 



rrij 
~N 



For the j th observation, let Xij £ {0, 1} indicate whether the outcome of that observation was i. For fixed i, the 
Xij are independent. To obtain a bound on the error \q° st — we use Hoeffding's inequality [ ], which for a sequence 
of N independent and identically distributed random bits Xij with mean value Ej^jj] = qi implies that 



Pr 



1 



N 



3 = 1 



> 6 



< 2e 



-2NS 2 



for any S > 0. 



(4) 



7 



So 

PrOgf* -*!><] <2e- 2 ^ 2 
for each i individually, and, by a union bound, 

Pr [|g? st - qi\ > S for any i] < 2de~ 2Ns2 . 

Choosing iV = [Jj In ^] makes the right hand side < e. Each of the N repetitions of quantum state restoration 
takes an expected time % • d, so the total expected number E[Msr] (where the subscript stands for "state restoration") 
of uses of P is 



E[M S r] = X ■ d 



1 , 2d' 



B. Improved algorithms to estimate measurement statistics 

In this section we describe two other algorithms which can be used for single-copy tomography. Both of these 
approaches are based on Jordan's lemma [5j. The algorithms we discuss in this section are based on the QMA 
amplification schemes of Marriott and Watrous [(i] and Nagaj et al. [8]. 

To use these algorithms, we fix i € {1, . . . , d} and we will estimate 



We repeat this for each value of i. 
We begin by defining the projector 



and the states 



Tr [psNMili 



-Q l 



1 



(i - Qi) 



Note that we can write 



(3) 



We also define the state 

\i>i) = -Vi-ufa) + V^\ v i)- 

We can then use the above expressions to write \vi) and in terms of and 

\v^) = V^Qil^ + VQil^)- 



(6) 



(7) 



The principal angle 6i £ [0, f ] between the two bases IV'T 1 )} and {\vi), \v^~)} is defined by 



cos 2 6i 



(8) 



Having defined the two bases {\vi), \v^~)} and we are now ready to describe two algorithms for computing 

the expectation value qi more efficiently than by using quantum state restoration. For any chosen e and 6, each of 
these algorithms will generate an estimate qf st such that |g| st — qi\ < 6 with probability at least 1—5- Repeating for 
each i, we have |g| st — qt\ < 8 for all i with probability at least 1 — e by a union bound. The running times of these 
algorithms as a function of <5 and e are summarized in Table I. 
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1. Alternating Projections 



This algorithm is an application of the scheme of Marriott and Watrous [ ] which was originally proposed for 
witness-reusing amplification of the complexity class QMA. Observe from (5), (6) and (7) that when performing the 
measurement P on the state the probability of obtaining 1 (and the state is qi. Similarly, when measuring 
P on the state |i>i~), the probability of obtaining (and the state \tpi~)) is also qi. We can estimate by performing 
many alternating measurements of P and Qi and counting the number of transitions \vi) ■<-» or \v^-) o )■ Let 
us now present the algorithm and compute its complexity measured by the expected number of measurements of P, 
as a function of the desired precision 8 and error probability | . 



1. Start with the state \ih). Fix N 



2. Repeat for t = 1, . . . , N 



In 



(a) Measure Qi and record the measurement outcome as a bit ait-\ & {0, !}■ This produces one of the two 
states \vi) or ). 

(b) Measure the projector P = and record the result a^t € {0, 1}. This produces either the state \ip) or 

3. If the state is not currently (because the last measurement in step 2b gave a 0), then the state is \ip^). In 
this case alternate measuring Qi and P until you recover 

4. From the list (ai, . . . , a2_/v), compute the list of differences (Ai, A2, A.2N-1) where Aj = aj+i ffi ay. Let m 
denote the number of zeros in this list of differences. Then the estimate of q is given by 

(9) 



2N- 1 



As discussed above, the probability of getting a measurement outcome (1 or 0) which is the same as the previous 
measurement outcome is qi. So the number of zeros which appear in the list (Ai, A2, A2at_i) is a binomial random 
variable with mean qi(2N — 1). This is why (9) gives an estimator for the value of qi. 

We now show that the estimate q° st from (9) has the required precision 5, with probability at least 1 — e. To show 
this, we again use Hoeffding's inequality (4). Applying this to the case at hand with qk = 1© A& for k £ {1-.., 2N — 1}, 
we obtain 



The choice N = 



log M 

452 



Thus we have shown that the desired 



guarantees that the right hand side is < 
precision S is achieved by our scheme with probability at least 1 — |. 

We now derive the expected number E[M^p] (AP stands for alternating projections) of uses of P in the above 

algorithm. The random variable M^p is N plus the number of additional uses of P in step 3. The operation composed 
of measuring Qi and then measuring P is an update of a symmetric random walk on the two states {\if>) , \ipi~}} ■ Let 
w (r) be the probability of transitioning from \if)) to in r steps. Then with probability 1 — w (N) step 3 does 
not use P at all and, with probability w (N) it uses an expected number invocations of P. Thus the expected 
running time of the algorithm is 



E 



M 



« 

AP 



N + w(N) 



< 2N. 



w(l) 



In the last line, we used the fact that w (N) is less than or equal to the probability of at least one transition occurring 
in N steps, which is at most Nw (1) by a union bound. 
Hence 



E[M^ P ] < 2 



1 , 2d 

TFo m — 

45 2 e 



Repeating this procedure to obtain estimates of each qi (which are all within the desired precision 5 with probability 
at least 1 — e) takes the expected running time 
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2. An improved algorithm using phase estimation 



In this section we will give an improved algorithm for single-copy tomography using phase estimation, based on 
a fast QMA amplification scheme given in [8]. Its advantage over the previous two algorithms is that it requires 
quadratically fewer measurements of P . The results of this section will prove Theorem 2. 

As in the previous section, we estimate the qi one at a time for i £ {1, . . . , off. 

We begin by defining the unitary operator 

Wi = (2P-I)(2Qi-I), 

which is a product of two reflections. Note that if we can implement P so that it coherently xors its measurement 
outcome into an ancilla register (as in the assumption of theorem 2), then we can implement the operator (2P — I) 
by first initializing that ancilla to |— ) and applying the measurement. 

Within the 2D subspace Si spanned by the vectors and (7), the operator Wi is a rotation 



Si 



(10) 



where 9i is the principal angle as defined in (8) (and a y refers to the Pauli matrix). 



We now describe how to obtain q t 
state \ip). The eigenvectors of Wi are 



cos Qi by running phase estimation of the operator Wi on the 



V2 



(ii) 



and correspond to eigenvalues e T^<l>i ^ where fa = so that < fa < | . After running phase estimation of Wi on 
the input state \ip), we will likely measure a good approximation to either fa or 1 — fa. Note that either outcome 
provides a good estimate of 



qi = cos 2 {it fa) 



\n(l-fa)). 



This is the idea of the algorithm we present in this section. Our algorithm must have a failure probability lower than 
that obtained by a single use of phase estimation, and we must recover the state \ip) at the end of the algorithm. 
Our algorithm begins by defining 



t 



log 2 



3tt 



+ 2. 



loe 



log 2 



(12) 



We proceed as follows: 

1. Start in the state \ip}\0} (g ' t . 

2. Repeat for j = 1, ...,r: 

(a) Reset the t qubits of the second register to the state |0)®*. Perform phase estimation of the operator Wi 
on the state of the first register, computing the phase using the t ancillae in the second register. Define 



cos 2 (tt4>^ 



where (j>^ is the measured phase, 
(b) Measure the projector P = \tp)(ip\ on the first register. 

If the state is not currently \ip) (because the last measurement in step 2(b) gave a 0), then the state is 

In this case repeat phase estimation followed by measurement of P until you measure a 1 for P, recovering the 

state 



4. Let q\ st be the median of the values {qf '} for j £ {1, ...r} 
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We now determine the expected runtime of this algorithm, and then we will show that the resulting estimate qf st 
achieves the desired precision with high enough probability. Our analysis of the runtime is based on the observation 
that each iteration of phase estimation followed by measurement of P is an update of a random walk on the two states 
{|V), IVi 1 )}- If we start in state |V) of the first register then after applying phase estimation (but before measuring 
the phase) we obtain a state 

I^) = -L(l^)| 7 ) + I0-)| M }). 

where (7) and are i-qubit states. So the probability of measuring 1 in step 2b is 

Pr [|V) -> |V)] = Tr [(|V)(VI ® I) 
in which case the resulting state of the first register is \ip). The probability of measuring a zero in this step is 



Pr 



|V X >] =Tr[(|^ X )^ X |®l)l^)(^l] = 1 - Pr [|V) -HV>>] 



in which case the resulting state of the first register is \ip~ L )- Similarly, one can compute the transition probabilities 
starting from the state \ip ± ) of the first register. These satisfy 

Pr [| V^) | V^)] = Pr [|V) ~> IV)] 
Pr[|V X >^|V)] = Pr [IV) -> |V X >] 
so the random walk is symmetric. We can then directly apply our analysis of the previous section to show that 
E[# of uses of phase estimation followed by measurement of P] < 2r. 

Each time we use phase estimation with t ancillae, we use the gate Wi less than 2* times [9]. So each time we 
repeat phase estimation followed by measurement of P we use less than 2* + 1 measurements of P so the expected 
total number of times E[Mpg] (PE stands for phase estimation) that we use the measurement of P is 

E[AfW] < 2r • (2* + 1) 

/127T 

< 2r 



1 



1 



l°g 2 



12tt 



1 



*** (7l) 

Repeating this procedure to obtain estimates of each qi takes expected running time 



E[M PE ] < 2d 



l°g 2 (£) 



12vr 



1 



(13) 



We now show that the probability that all the estimates qf st obtained by using the above algorithm satisfy 

\qt st -Qi\<S 

is at least 1 — e. Our choice of t was designed so that the output of phase estimation of Wi on the state \4>f) using 
t ancillae is a state \(f)f such that a measurement of the t-qubit state (7) in the computational basis produces a 
phase (f> that satisfies 



\4>-<t>i\ < 



3?r 



with probability at least |[ ]. Similarly the output of phase estimation of Wi on the state \4>i ) using t ancillae is a 
state \(f>^)\fi) such that a measurement of the i-qubit state |/x) in the computational basis produces a phase <fi that 
satisfies 



10 — (1 — 001 < 



3?r 
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State Restoration Alternating Projectors Phase Estimation 


E[M SR ] = 0(*#logf) 


E[M AP ] = 0(£logf) 


E[M PB ] =0(| log (&)) 



Table I: Scaling of the expected number of measurements of P = \t[>){tp\ used by each algorithm as a function of the desired 
precision S and error probability e. 



with probability at least §. In step 2(a) of our algorithm we perform phase estimation on cither the state \ip) or 
the state In either case, the reduced density matrix of the f-qubit ancilla register after applying the phase 

estimation (but before measuring the phase) is 

^(ItXtI + ImXmI) 

which is an equal probabilistic mixture of I7) and So, with probability at least | (regardless of whether we started 
in \ip) or IV^)), the phases <f)f' measured in step 2 of the algorithm satisfy either 

or 

l#-(l-0 4 )l<^. 

Using the inequality 

I cos 2 (7ra) - cos 2 (tt/3)| < 27r|a - /3\ 
and the fact that cos 2 (7ra;) = cos 2 (7r(l — x)) it follows that the estimates qf^ each (independently) satisfy 

\lP-QiK8 

with probability at least | . The median lemma of [8] says in this case that the probability that the median of the 
r independent measured values qf^ falls outside the interval {qi — 5,qi + 8) is upper bounded as pf a ;i < \ (^r) • 
Plugging in our choice of r from Eq. 12 gives 

\q! st -qi\<6 

for each i with probability at least 1 — 4. So the probability that the above inequality is satisfied for all of the 
i E {1, ...d} is at least 1 — e. 



C. Performance comparison for estimating measurement statistics 

These three algorithms for estimating the probabilities = Tr [pb\t) b(*|s] gi ve estimates {q° st } (for i from 1 to d) 
which are all within 5 of the correct values with probability at least 1 — e. Their running times are summarized in 
table I. 

State restoration is conceptually the simplest of the three algorithms, and we expect that it will be sufficient for 
most purposes. It is also the slowest as a function of d and 6 (assuming x IS increasing as a function of d). The 
state restoration algorithm has the advantage that we can drop in different tomography schemes that may improve 
performance. 

In the absence of a better tomography scheme, however, both other algorithms outperform state restoration as a 
function of d. Phase estimation also performs quadratically better than both other algorithms as S — > 0. 



IV. APPLICATIONS OF QUANTUM STATE RESTORATION AND SINGLE-COPY TOMOGRAPHY 

A. Breaking quantum money 

As we discussed in the introduction, quantum money is the idea of using a state as money — that is, something that 
can be passed around but not forged. The money consists of a quantum state and a verification procedure which 
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should succeed with high probability on valid money issued by the bank but should fail with high probability for any 
efficiently forgeable state. The first quantum money protocols [3, 11] required the verification procedure to be secret, 
so only the bank (i.e. the issuer of the money) could verify money states. There is recent interest in publicly verifiable 
quantum money [1, 2, 7], in which everyone, including a would-be forger, has access to the verification procedure. In 
the introduction, we showed that quantum state restoration breaks quantum money based on product states. More 
generally, as a corollary of Theorem 2, any quantum money protocol in which the verifier is a projector must be 
designed to withstand attacks based on single-copy tomography. If the verifier is a projector, then an adversary can 
use single-copy tomography to learn the measurement statistics of any efficiently implementable measurement with a 
small number of outcomes on the quantum money state \ip). 

B. Studying ground states of many-body Hamiltonians 

Quantum computers offer potentially exponential speedups in simulating quantum mechanics, but some problems 
are still hard. For example, preparing ground states of many-body systems generically takes exponential time in 
the number of particles. Nonetheless, for sufficiently small systems with large enough energy gaps, algorithms such 
as [10] may run quickly enough to prepare a single copy of the ground state, and phase estimation can be used to 
verify the ground state. Single-copy tomography allows us to make multiple tomographic measurements (even of 
nonarxcommuting operators) on small numbers of particles without having to prepare multiple copies of the ground 
state. This gives a large speedup over traditional tomography. 

Single-copy tomography could also be useful to characterize the ground state during adiabatic evolution. This 
information could even be used in real time to guide the choice of path for an adiabatic algorithm. 

V. CONCLUSIONS 

It is strongly believed that the ability to verify an unknown state \ip) does not give the ability to produce that state 
efficiently. Without the ability to verify a state, mere possession of that state confers little power. As we have shown, 
the combination of a verifier and a single copy of \ip) is more powerful that either one alone. 
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